California SB 690 Signed: CIPA Pen Register Suits AG-Only in 2027
Independently fact-checked against primary sources (last audited October 1, 2026). · 9 primary sources cited on this page. How we verify our legal content

California SB 690 Signed: Private CIPA Pen Register Suits Over Website Tracking Barred From 2027
Governor Gavin Newsom signed Senate Bill 690 on September 30, 2026, and the Secretary of State chaptered it the same day as Chapter 976. Starting January 1, 2027, only the Attorney General may bring a private-actor pen register claim under California's wiretap chapter arising from website conduct.
Information last verified on October 1, 2026.
Status: Approved by the Governor and chaptered by the Secretary of State as Chapter 976, Statutes of 2026, both on September 30, 2026. The enrolled text contains no urgency clause and sets no specified operative date, so under California Constitution article IV, section 8(c)(1) the statute goes into effect January 1, 2027. It is enacted; it is not yet in force.
Jurisdiction scope: This article covers California state law only, specifically the California Invasion of Privacy Act at Penal Code sections 630 through 638.55. It does not cover the federal Wiretap Act or the federal pen register statute at 18 U.S.C. sections 3121 through 3127, and it does not cover California's consumer privacy statutes, which are a separate body of law described in our guide to California data privacy rules.
What Happened
Senate Bill 690 was introduced by Senator Anna Caballero on February 21, 2025, with Senators Niello and Valladares and Assembly Members Irwin, Macedo, and Blanca Rubio as coauthors. The Legislature's official action log records the final sequence: the Assembly read the bill a third time and passed it on August 28, 2026 by a vote of 66 to 0, the Senate concurred in the Assembly amendments the same day by 39 to 0, the enrolled version is dated August 31, 2026 and the log records the bill "Enrolled and presented to the Governor at 2 p.m." on September 4, 2026, and on September 30, 2026 the log records both "Approved by the Governor" and "Chaptered by Secretary of State. Chapter 976, Statutes of 2026."
The bill is short. Section 1 rewrites Penal Code section 637.2, and Section 2 is a severability clause. The operative change is a new subdivision (d), which reads in full:
(d) (1) An action against a private actor for a violation of Section 638.51 alleged to arise from conduct occurring on an internet website, online application, or mobile application may be brought under this section only by the Attorney General.
(2) The amendments to this section by Senate Bill No. 690 of the 2025-26 Regular Session apply retroactively to any pending claim in an action commenced within two years before the operative date of that legislation.
Pinpoint: Cal. Penal Code sec. 637.2(d), as amended by Stats. 2026, ch. 976, sec. 1 (SB 690, 2025-26 Reg. Sess.), enrolled text as of August 31, 2026.
Section 1 also threads the new carve-out through the rest of the statute. Subdivisions (a) and (b), which create the damages claim and the injunction claim, now open with "Except as provided in subdivision (d)." The savings clause that is currently subdivision (d), which states that section 637.2 is not to be construed to affect the Uniform Single Publication Act at Civil Code Title 4 (commencing with Section 3425.1), is renumbered to subdivision (e) without substantive change.
The Legislative Counsel's Digest describes the change in the same narrow terms, stating that the bill "would instead authorize only the Attorney General to bring that action for a violation of the above-described provision if the action is alleged to arise from conduct occurring on an internet website, online application, or mobile application." The Digest Key on the enrolled bill records a majority vote requirement, no appropriation, and no state-mandated local program.
The signing message
The Governor issued a signing message to the Members of the California State Senate dated September 30, 2026. It states:
I am signing Senate Bill 690, which eliminates the private right of action under the California Invasion of Privacy Act (CIPA) for violations of the pen register and trap-and-trace statute arising from conduct occurring on an internet website, online application, or mobile application.
The message describes the problem the Governor understood the bill to address as "the vexatious use of CIPA lawsuits and demand letters to extract settlement money from small businesses that unwittingly install software on their websites that at times have tracked and shared the information of visitors to the site." It then flags the bill as incomplete:
However, additional work in this area is needed, as CIPA contains other decades-old statutes that are also susceptible to abuse by overly aggressive litigants. I urge the Legislature to take this on next year to ensure a fair balance between protecting private information and preventing rapacious litigation.
The message is published as a scanned letter on the Governor's website and carries a September 30, 2026 date stamp and the Governor's signature.
What the Law Actually Says
The California Invasion of Privacy Act is Chapter 1.5 of Title 15 of Part 1 of the Penal Code, added by Statutes of 1967, chapter 1509. Our plain-language explainer of CIPA walks through the chapter section by section; the three provisions that matter for SB 690 are summarized here.
Section 637.2 is the money. In its current form, last amended by Statutes of 2016, chapter 855 (AB 1671), it lets any person injured by a violation of the chapter recover the greater of five thousand dollars per violation or three times actual damages, lets any person sue to enjoin a violation, and expressly says that actual damages are "not a necessary prerequisite" to the action. That last clause is the mechanism behind the CIPA filings and demand letters the Governor's signing message describes: a plaintiff who cannot show out-of-pocket loss can still plead the statutory figure. SB 690 leaves all of that intact except for the one category it reserves to the Attorney General.
Section 638.51 is the prohibition SB 690 targets. Added by Statutes of 2015, chapter 204 (AB 929), it provides that, except as stated in subdivision (b), "a person may not install or use a pen register or a trap and trace device without first obtaining a court order pursuant to Section 638.52 or 638.53." Subdivision (b) lists provider-side exceptions, including operating and testing the service, protecting the provider's rights or property, protecting users from abuse of service, and, at subdivision (b)(5), use "if the consent of the user of that service has been obtained." Under subdivision (c) a violation is punishable by a fine not exceeding $2,500, by imprisonment in the county jail not exceeding one year, by imprisonment pursuant to Penal Code section 1170(h), or by both fine and imprisonment, and subdivision (d) makes good-faith reliance on a court order or authorization a complete defense.
Section 638.50 supplies the definitions that made web claims possible. It defines a pen register as "a device or process that records or decodes dialing, routing, addressing, or signaling information transmitted by an instrument or facility from which a wire or electronic communication is transmitted, but not the contents of a communication," and a trap and trace device as a process that captures incoming impulses identifying "the originating number or other dialing, routing, addressing, or signaling information reasonably likely to identify the source of a wire or electronic communication." Those definitions speak to routing and identifying data rather than content, and they are written in terms of a "device or process" rather than of telephone equipment alone.
What SB 690 does not touch is as important as what it does. Section 631, the wiretap provision, still reaches a person who "willfully and without the consent of all parties to the communication" reads or attempts to learn the contents of a message in transit, and still carries the section 637.2 private action. Section 632.7 still reaches recording a communication involving a cellular or cordless telephone "without the consent of all of the parties," and also still carries the private action. California's all-party consent rule, which we cover in detail in California's recording and consent rules, is unchanged by this bill. So is the general availability of CIPA claims against defendants who are not private actors, and section 638.51 claims that do not arise from website, online-application, or mobile-application conduct.
The retroactivity clause is written in terms of pending claims rather than filing dates alone. Section 637.2(d)(2) reaches "any pending claim in an action commenced within two years before the operative date of that legislation." Two conditions are stated on the face of the text: the claim must be pending, and the action must have been commenced within the two-year window measured back from the operative date. We flagged this clause when the bill was still on the Governor's desk, in our earlier walkthrough of the SB 690 carve-out, and the enrolled text matches what the Legislature sent up.
Analysis: Why This Matters
The following is analysis from the Recording Law Editorial Team.
One way to get this bill wrong is to describe it as a CIPA exemption for businesses. It is not. The statute does not make any conduct lawful. Section 638.51 still prohibits installing or using a pen register or trap and trace device without a court order, and the criminal penalty in section 638.51(c) is untouched. What changed is who may sue under section 637.2 for one defined slice of that prohibition. A business whose website conduct would have violated section 638.51 on December 31, 2026 stands in exactly the same position on January 1, 2027 as a matter of what the statute forbids. What differs is that enforcement of that prohibition, in that setting, runs through the Attorney General rather than through private plaintiffs.
The carve-out is also narrower than the headline suggests, because it has three cumulative elements and each one is a boundary. The defendant must be a "private actor," a phrase the bill does not define. The claim must be "for a violation of Section 638.51," which leaves claims pleaded under sections 631 or 632.7 outside the bar even when they arise from the same tracking technology. And the conduct must occur "on an internet website, online application, or mobile application," which leaves section 638.51 claims arising elsewhere untouched. Because the bar is keyed to section 638.51 alone, a complaint that also pleads sections 631 or 632.7 keeps those counts, so the bar removes one count rather than every count arising from the same conduct. The Governor's own message recognizes this by naming "other decades-old statutes" as unfinished business and asking the Legislature to return to the subject next year.
Two structural features deserve attention. First, the bill creates exclusive Attorney General enforcement for this category without appropriating anything; the Digest Key records "Appropriation: NO." The statute therefore reassigns an enforcement function to the Attorney General's office without attaching new funding to it. Second, the severability clause in Section 2 is doing real work: if the retroactivity provision in subdivision (d)(2) were held invalid as applied to some claim, Section 2 provides that the invalidity does not affect other provisions or applications that can be given effect without it, which on its face leaves the prospective bar in subdivision (d)(1) standing.
On retroactivity we will describe only what the statute says. Subdivision (d)(2) by its terms applies the amendments to pending claims in actions commenced within two years before the operative date. How that language is applied in any particular case is a question for the court handling it, and we are not predicting any outcome.
How This Affects You
These are general observations, not advice about any specific situation.
For a California website or app operator, the compliance picture is unchanged. The provider-side consent exception at section 638.51(b)(5) and the good-faith court-order defense at section 638.51(d) remain the statutory defenses they were, the separate obligations under California's consumer privacy statutes are not mentioned in the bill, and the same tracking configuration that generated a section 638.51 count can still generate counts under sections 631 and 632.7, which is the pattern described in our coverage of recent California pixel and wiretap filings.
For a California consumer, the change is in remedy rather than in what section 638.51 prohibits. After the operative date, the enforcement route for the covered category is the Attorney General rather than an individual suit under section 637.2; other CIPA theories and other California privacy statutes are unaffected. Anyone holding a demand letter that cites section 638.51 and website conduct has two dates that matter, September 30, 2026 and January 1, 2027, and one text that matters, subdivision (d) in full. Those are facts to bring to a lawyer, not conclusions to act on alone.
What Happens Next
Through December 31, 2026, the current statute governs. The version of section 637.2 in force today is the 2016 version, with no subdivision (d) carve-out. Enactment on September 30, 2026 did not change the operative text; under California Constitution article IV, section 8(c)(1), a statute enacted at a regular session "shall go into effect on January 1 next following a 90-day period from the date of enactment," which for a September 30, 2026 enactment is January 1, 2027.
On January 1, 2027, subdivision (d) becomes operative, and the retroactivity sentence takes its measurement from that date. The two-year lookback in subdivision (d)(2) is tied to the operative date of the legislation, so the window it describes runs back from January 1, 2027 rather than from the signing date.
Application to pending cases will be worked out in court. The statute states the rule; it does not create an administrative process, a filing deadline, a claims procedure, or any implementing regulation. Nothing in the enrolled text directs the Attorney General to adopt rules or publish guidance.
A further CIPA bill is being invited, not promised. The Governor's September 30, 2026 message urges the Legislature "to take this on next year," which points at the 2027 portion of the next session. No such bill exists yet, and a signing message does not bind a future Legislature.
This article is legal information, not legal advice. Reading it does not create an attorney-client relationship. California statutes are amended regularly and a pending case may turn on facts and procedural history not described here. Consult a licensed California attorney about your own situation before acting.
Related articles
- The California Invasion of Privacy Act explained
- Our September walkthrough of the SB 690 pen register carve-out
- California recording and all-party consent rules
- California pixel and wiretap litigation coverage
- California data privacy laws
- The California privacy and surveillance bills that were awaiting the Governor
Last updated: 2026-10-01. Details verified as of 2026-10-01.
Frequently Asked Questions
Does SB 690 repeal the California Invasion of Privacy Act?
No. SB 690 amends only Penal Code section 637.2, the civil-remedy provision, and adds a subdivision stating that an action against a private actor for a violation of section 638.51 arising from website, online-application, or mobile-application conduct may be brought only by the Attorney General. Every prohibition in CIPA, including section 638.51 itself and its criminal penalty, remains on the books in California.
When does SB 690 actually take effect?
January 1, 2027. The bill was approved by the Governor and chaptered as Chapter 976, Statutes of 2026 on September 30, 2026, but the enrolled text contains no urgency clause, so California Constitution article IV, section 8(c)(1) supplies the default: a statute enacted at a regular session goes into effect on January 1 next following a 90-day period from enactment.
Can a private plaintiff still sue under Penal Code section 631 or 632.7 in California?
Yes. SB 690 amends only section 637.2 and limits only claims brought for a violation of section 638.51 arising from website or app conduct. Sections 631 and 632.7 are not amended, and the section 637.2 private action remains available for them.
What does the retroactivity provision in SB 690 say?
New Penal Code section 637.2(d)(2) provides that the amendments 'apply retroactively to any pending claim in an action commenced within two years before the operative date of that legislation.' Because the operative date is January 1, 2027, the two-year window the text describes is measured back from that date. How the provision applies to any individual case is for the court handling that case.
Does SB 690 make website tracking legal in California?
No. Penal Code section 638.51 still prohibits installing or using a pen register or trap and trace device without a court order, subject to the provider-side exceptions in subdivision (b), and a violation is still punishable under subdivision (c) by a fine not exceeding $2,500, by imprisonment in the county jail not exceeding one year, by imprisonment pursuant to Penal Code section 1170(h), or by both fine and imprisonment. SB 690 changes who may bring one category of civil action, not what the statute forbids.
Who can enforce section 638.51 against a website operator after January 1, 2027?
For claims against a private actor arising from conduct on an internet website, online application, or mobile application, new section 637.2(d)(1) provides that the action may be brought under section 637.2 only by the California Attorney General. The bill makes no appropriation for that enforcement; the enrolled bill's Digest Key records 'Appropriation: NO.'
What was the vote on SB 690 in the California Legislature?
The official action log records an Assembly third-reading vote of 66 ayes and 0 noes on August 28, 2026, and Senate concurrence in the Assembly amendments the same day by 39 ayes and 0 noes. The Senate had passed an earlier version 35 to 0 on June 3, 2025.
Did the Governor say anything about further CIPA changes?
Yes. In his September 30, 2026 signing message, Governor Newsom wrote that 'additional work in this area is needed, as CIPA contains other decades-old statutes that are also susceptible to abuse by overly aggressive litigants,' and urged the Legislature 'to take this on next year.' That is a request, not enacted law.
What happens if a court strikes down part of SB 690?
Section 2 of the bill states that its provisions are severable and that invalidity of one provision or application does not affect other provisions or applications that can be given effect without it. On its face that would leave the prospective bar in section 637.2(d)(1) standing even if the retroactivity sentence in (d)(2) were held invalid in some application.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- California Legislative Information, SB-690 Crimes: invasion of privacy, complete bill history. Records 'Approved by the Governor' and 'Chaptered by Secretary of State. Chapter 976, Statutes of 2026' both on 09/30/26, Assembly third reading passage 66-0 and Senate concurrence 39-0 on 08/28/26, enrollment 08/31/26 and presentment to the Governor 09/04/26 at 2 p.m. Establishes the enactment and chaptering facts and the vote tallies. Accessed 1 October 2026.(leginfo.legislature.ca.gov).gov
- California Legislative Information, SB 690 (Caballero), enrolled text of 08/31/26, 2025-26 Regular Session. Section 1 amends Penal Code section 637.2 to add subdivision (d)(1) reserving private-actor section 638.51 website and app claims to the Attorney General and subdivision (d)(2) applying the amendments retroactively to pending claims in actions commenced within two years before the operative date; Section 2 is the severability clause; the Legislative Counsel's Digest and Digest Key record a majority vote requirement and no appropriation. Establishes the full operative text and confirms the absence of any urgency clause. Accessed 1 October 2026.(leginfo.legislature.ca.gov).gov
- Office of the Governor of California, signing message for Senate Bill 690 addressed to the Members of the California State Senate, dated September 30, 2026, signed Gavin Newsom. States that the bill 'eliminates the private right of action under the California Invasion of Privacy Act (CIPA) for violations of the pen register and trap-and-trace statute arising from conduct occurring on an internet website, online application, or mobile application' and urges the Legislature to address CIPA's 'other decades-old statutes' next year. Establishes the Governor's stated rationale and his call for further legislation. Accessed 1 October 2026.(gov.ca.gov).gov
- California Penal Code section 637.2, as amended by Stats. 2016, ch. 855, sec. 4 (AB 1671), effective January 1, 2017. The version in force through December 31, 2026: statutory damages of the greater of $5,000 per violation or three times actual damages, injunctive relief, and the rule that actual damages are 'not a necessary prerequisite' to the action. Establishes the baseline CIPA civil remedy that SB 690 narrows. Accessed 1 October 2026.(leginfo.legislature.ca.gov).gov
- California Penal Code section 638.51, added by Stats. 2015, ch. 204, sec. 2 (AB 929), effective January 1, 2016. Prohibits installing or using a pen register or trap and trace device without a court order under section 638.52 or 638.53, lists the provider-side exceptions in subdivision (b) including user consent at (b)(5), sets a fine not exceeding $2,500 or county jail under (c), and makes good-faith reliance on an order a complete defense under (d). Establishes the prohibition SB 690's carve-out attaches to and confirms the prohibition itself is unchanged. Accessed 1 October 2026.(leginfo.legislature.ca.gov).gov
- California Penal Code section 638.50, definitions for the pen register and trap and trace article. Defines a pen register as a device or process recording dialing, routing, addressing or signaling information 'but not the contents of a communication' and a trap and trace device as one capturing incoming impulses identifying the source of a communication. Establishes the statutory definitions web-tracking claims under section 638.51 rely on. Accessed 1 October 2026.(leginfo.legislature.ca.gov).gov
- California Penal Code section 631, part of Chapter 1.5 (Invasion of Privacy) added by Stats. 1967, ch. 1509. Reaches a person who 'willfully and without the consent of all parties to the communication' reads or attempts to learn the contents of a message in transit. Establishes that section 631 is not amended by SB 690 and retains the section 637.2 private action. Accessed 1 October 2026.(leginfo.legislature.ca.gov).gov
- California Penal Code section 632.7. Reaches intentional recording of a communication involving a cellular or cordless telephone 'without the consent of all of the parties to a communication.' Establishes that section 632.7 is likewise untouched by SB 690 and retains the section 637.2 private action. Accessed 1 October 2026.(leginfo.legislature.ca.gov).gov
- California Constitution, article IV, section 8(c)(1). Provides that, except as stated in paragraphs (2) and (3), 'a statute enacted at a regular session shall go into effect on January 1 next following a 90-day period from the date of enactment of the statute.' Establishes the January 1, 2027 operative date for a statute enacted September 30, 2026 with no urgency clause. Accessed 1 October 2026.(leginfo.legislature.ca.gov).gov